Stored XSS Vulnerability in pfSense Plus and Community Edition
CVE-2026-56128
5.1MEDIUM
What is CVE-2026-56128?
An authenticated user with permission to edit firewall schedules in pfSense Plus and Community Edition can exploit a stored XSS vulnerability. By injecting arbitrary JavaScript into the schedule description via the descr parameter in the firewall_schedule_edit.php file, the malicious payload is saved and executed in the browsers of users who access the corresponding firewall rules. This occurs due to insufficient HTML sanitization, allowing certain JavaScript code to bypass protections and lead to potential unauthorized access to sensitive data or user sessions.
Affected Version(s)
pfSense CE 0
pfSense Plus 0 < 26.07
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Williams from Pellera Technologies
VulnCheck
